CAF v4 in the DSPT: What NHS England's Cyber Framework Actually Means for Your Toolkit
DSPT version 9 for 2026-27 is built on version 4.0 of the NCSC's Cyber Assessment Framework (CAF). But "aligned to CAF v4.0" means something different depending on what kind of organisation you are, and it's worth understanding the actual mechanics rather than assuming DSPT and CAF are the same thing wearing different names.
What is CAF v4
The Cyber Assessment Framework is the National Cyber Security Centre's (NCSC) framework for assessing cyber resilience. Version 4.0, released in 2025, sharpened coverage of supply chain security, threat detection capability, and AI-related risk. It's structured around four objectives: managing security risk, protecting against cyber attack, detecting security events, and minimising impact, each broken down into principles and outcomes, assessed against Indicators of Good Practice.
CAF was designed for organisations providing essential services, most regulated under the NIS Regulations. It's a self-assessment and audit methodology rather than a pass/fail exam, and NCSC doesn't issue a certificate at the end of it.
How DSPT is Built On CAF
Since September 2024, NHS England has been moving DSPT away from the old National Data Guardian 10 standards onto a framework built on CAF, but not as a straight copy. NHS England and DHSC added a fifth objective, Objective E ("Using and Sharing Information Appropriately"), covering transparency, individual rights, data sharing and records management, an addition that doesn't exist in NCSC's own CAF.
This fully CAF-structured version of DSPT currently applies to NHS trusts and foundation trusts, ICBs, DHSC arm's-length bodies, CSUs, DHSC-nominated genomics organisations, and independent providers formally designated Operators of Essential Services (OES).
Where Category 2 IT Suppliers Fit
If you're a Category 2 IT supplier (and not separately designated an OES, which is unusual), you're not on that CAF-objective structure at all. Your DSPT is still built around assertions and evidence items, the format you'll recognise from previous years, rather than CAF's Objectives A–E.
What has changed for 26-27 is that the evidence base itself has been refreshed to reflect CAF v4.0's priorities. That's where new requirements come from:
-
A new mandatory requirement (4.5.6) that software supplied to health and care organisations supports multi-factor authentication or identity federation to industry standards, or has a credible, resourced plan to get there, by 30 June 2027.
-
A new mandatory requirement (9.5.11) that software is developed in line with the government's Software Security Code of Practice.
-
A reworked requirement (9.5.10) around signing the Supply Chain Charter.
It's influence, not adoption: you're evidencing outcomes that trace back to CAF v4.0's thinking on supply chain security and identity, without being run through CAF's own assessment process. NHS England has said DSPT/CAF alignment "will continue to progress," so this looks like a direction of travel rather than a finished state, if Category 2 suppliers do eventually move onto a fully CAF-structured version of DSPT, we'll cover it here.
What This Means Day to Day
For most suppliers, the CAF v4 shift shows up as a handful of new or reworked evidence items rather than a new framework to learn from scratch. Prioritise the MFA/identity federation requirement; the deadline is firm, and "credible, resourced plan" evidence takes longer to build than people expect. Read the Software Security Code of Practice item in full if your organisation writes its own software.
FAQs
Is CAF a certification scheme? +
No. NCSC's Cyber Assessment Framework is a self-assessment and audit methodology used to judge cyber resilience against a set of outcomes. It doesn't issue certificates, and there's no formal "CAF certified" status for any organisation.
If we complete this year's DSPT, does that mean we're also certified to CAF version 4? +
No — a question we were asked directly by a customer working through DSPT 26-27, and worth answering precisely. Completing DSPT means you've been assessed against NHS England's own toolkit, which for some organisation types is now structured around CAF v4.0's outcomes. It doesn't mean NCSC has certified you against CAF, because CAF doesn't produce a certificate for anyone, supplier or NHS trust alike.
Does the CAF-aligned DSPT mean an organisation is CAF certified? +
No. The CAF-aligned DSPT is NHS England's own toolkit, built on a health-and-care adaptation of CAF's structure (including Objective E, which isn't part of NCSC's original framework). Completing it is an NHS England assessment, not an NCSC certification.
Are Category 2 IT suppliers on the CAF-aligned DSPT? +
Not currently. Category 2 IT suppliers (unless separately designated an Operator of Essential Services) still complete an assertion-based DSPT. For 26-27, the evidence items have been updated to reflect changes in CAF v4.0, but the toolkit isn't structured around CAF's objectives and outcomes the way the versions used by NHS trusts, ICBs and OES organisations are.
Will IT suppliers eventually move to the full CAF-aligned DSPT? +
NHS England has said the alignment between DSPT and CAF will keep progressing, so it's a reasonable direction of travel, but nothing has been confirmed for Category 2 suppliers as of DSPT 26-27.